VendorsMITkerberos4.0
Vulnerabilities

MIT Kerberos 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2000-0389
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
Published 2000-07-12 · Modified
10.03 PoCEPSS 0.165
CVE-2000-0390
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.
Published 2000-07-12 · Modified
10.0EPSS 0.040
CVE-2000-0391
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.
Published 2000-07-12 · Modified
10.0EPSS 0.040
CVE-2000-0392
Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.
Published 2000-07-12 · Modified
7.2EPSS 0.004
CVE-2000-0546
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.
Published 2000-07-12 · Modified
5.0EPSS 0.029
CVE-2000-0547
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.
Published 2000-07-12 · Modified
5.0EPSS 0.029
CVE-2000-0548
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.
Published 2000-10-13 · Modified
5.0EPSS 0.029
CVE-2000-0550
Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service.
Published 2000-10-13 · Modified
5.0EPSS 0.024
CVE-2000-0549
Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.
Published 2000-10-13 · Modified
5.0EPSS 0.023
CVE-1999-0143
Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.
Published 1999-09-29 · Modified
4.6EPSS 0.004